
WP Wapuu Widget Security & Risk Analysis
wordpress.org/plugins/wp-wapuu-widgetThis plugin adds a widget that shows the pretty official character of WordPress Japanese local site.
Is WP Wapuu Widget Safe to Use in 2026?
Generally Safe
Score 85/100WP Wapuu Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-wapuu-widget plugin, version 0.4.3, presents a mixed security profile. On the positive side, the plugin exhibits an extremely small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are correctly handled using prepared statements, and there are no file operations or external HTTP requests. The absence of any recorded vulnerabilities or CVEs in its history is also a strong indicator of robust security practices in previous development cycles.
However, the code analysis reveals significant concerns. The presence of the `create_function` is a major red flag, as it is deprecated and can lead to security vulnerabilities if not handled with extreme care, especially in older PHP versions. Additionally, a mere 20% of output is properly escaped, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks and capability checks on any potential entry points, though currently non-existent, means that if new entry points are added in the future, they would be inherently insecure without these critical safeguards. The taint analysis showing zero flows is positive, but this is likely a consequence of the very limited attack surface and functionality.
In conclusion, while the plugin benefits from a minimal attack surface and good database query practices, the insecure use of `create_function` and the widespread lack of output escaping create significant inherent risks. The absence of past vulnerabilities is encouraging, but the current code signals point to a need for immediate remediation, particularly regarding output sanitization and the removal of deprecated, insecure functions. The lack of authentication checks on the minimal entry points means that any future expansion of the plugin's functionality could easily introduce critical vulnerabilities.
Key Concerns
- Use of deprecated and insecure create_function
- Low percentage of properly escaped output (20%)
- No nonce checks present
- No capability checks present
WP Wapuu Widget Security Vulnerabilities
WP Wapuu Widget Release Timeline
WP Wapuu Widget Code Analysis
Dangerous Functions Found
Output Escaping
WP Wapuu Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
WP Wapuu Widget Maintenance & Trust
Maintenance Signals
Community Trust
WP Wapuu Widget Alternatives
Image Widget
image-widget
A simple image widget that uses the native WordPress media manager to add image widgets to your site.
Recent Posts Widget With Thumbnails
recent-posts-widget-with-thumbnails
List the most recent posts with post titles, thumbnails, excerpts, authors, categories, dates and more!
Image Hover Effects – Elementor Addon
image-hover-effects-addon-for-elementor
Add creative image hover effects to Elementor page builder. Easily customize title and content and effects with intuitive interface.
Meks Easy Photo Feed Widget
meks-easy-instagram-widget
Easily display Instagram photos as a widget that looks good in (almost) any WordPress theme.
Bellows Accordion Menu
bellows-accordion-menu
A flexible and robust accordion menu plugin
WP Wapuu Widget Developer Profile
8 plugins · 670 total installs
How We Detect WP Wapuu Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-wapuu-widget/wapuu_380.pngHTML / DOM Fingerprints
wapuu_widgetid="_wapuu_size"name="_wapuu_size"id="_wapuu_bg_color"name="_wapuu_bg_color"id="_wapuu_target"name="_wapuu_target"+6 more